Skip to main content
Contributor I
June 9, 2026

Impacted by spam bot attacks

  • June 9, 2026
  • 8 replies
  • 505 views

Hi Everyone,

I wanted to have a conversation about spam attacks on one of our stores which has been happening more frequently in the last 2 months. We’ve had our deliverability rates impacted and even our active profile count has increased which has impacted billing.

Support did help us with removing the profiles but this happens after the issue has happened and the damage has been done.

Has anyone else faced this and can give us a hand?

 

 

Thank you,

Anna

8 replies

CRM Global
Partner
Partner
June 13, 2026

Welcome to the community!

If you are seeing these profiles sharing the same domain on the email address, you could use mail ward from the app marketplace to block that domain entering your Klaviyo flows and it is free, so that might be worth a try otherwise if you enable double opt in that should hopefully stop them from entering your lists

Hope that gets resolved for you!

Contributor I
July 2, 2026

We are seeing a similar issue, was this the fix?

Contributor I
July 14, 2026

Somewhat, there is a limit on the domain blocking for free. I do appreciate the help!

CRM Global
Partner
Partner
August 5, 2026

Glad that worked for you, you can pair it with flow filter conditions but it wouldn’t auto suppress. You could use Klaviyo’s API in a custom solution for that instead though!

Tato
Contributor I
Contributor I
August 14, 2026

Hi Anna, we see this a lot in our projects. The key shift is blocking bots before they become profiles, because once they are in, they count towards billing and hurt deliverability.

A few things that work in practice:

Double opt-in is the single biggest lever. Bots almost never confirm, so they stay as inactive profiles you can suppress in bulk instead of active ones you pay for.

Second, validate at the form level. A honeypot field (hidden field that humans never fill, bots do) catches a lot. If you built a custom form, an email validation check before the subscribe call fires stops fake and mistyped addresses from ever reaching Klaviyo.

And set up a small routine: a segment for suspicious patterns (gibberish names, random letter combos, spikes of signups from one domain) that you review and suppress monthly. Suppressed profiles don't count towards your active count, so this keeps billing clean even when something slips through.

The domain blocking you set up is a good extra layer, but double opt-in plus form validation is what actually stops the inflow.

CRM Global
Partner
Partner
August 30, 2026

Really great points it definitely is becoming more and more common, some clients i worked with saw a massive drop in captures due to double opt in so they’ve used the email scan setup instead

Contributor I
August 24, 2026

One important distinction: if these profiles are being created through Shopify checkout rather than a Klaviyo signup form, double opt-in and form validation may not solve the entire problem. The bot can still create an abandoned checkout, which then syncs a profile into Klaviyo. Blocking one email domain also has limited value when the bots rotate domains and identities.

Full disclosure: I’m the founder of CartWatch. We built it specifically for Shopify merchants dealing with this problem. It detects bot-generated abandoned checkouts, automatically suppresses the associated profiles in Klaviyo, and separates them from genuine abandoned checkout data. It can also block suspicious checkouts from completing, helping reduce card-testing attempts.

No solution can promise that bots will never reach the store, but the goal is to stop them from polluting your Klaviyo account, increasing active-profile costs, and distorting your marketing data.

If anyone here is dealing with this specific Shopify-to-Klaviyo issue, I’m happy to answer questions or look at the pattern you’re seeing:

https://apps.shopify.com/cartwatch

Contributor I
September 15, 2026

I’ve been seeing this exact issue across a number of Shopify stores recently.

The difficult part is that by the time the fake profiles are cleaned up manually, they may already have increased your active profile count and potentially affected deliverability.

I’m the developer of CartWatch, a Shopify app we built specifically around this problem. It detects bot-created abandoned checkouts and can automatically suppress the associated profiles in Klaviyo, so they don’t continue sitting in your active profile count.

https://marketplace.klaviyo.com/en-us/apps/01kq4teeppg1mzwpqk2dat1w81/

It also tags the bot activity in Shopify and gives merchants a clean view of their real abandoned checkouts.

One important limitation: Shopify currently does not allow apps to delete the abandoned checkout itself from Shopify, so the focus is on identifying it quickly and preventing the downstream Klaviyo impact.

If you’re still dealing with this, I’d be happy to take a look at the pattern you’re seeing and tell you whether it looks like the same type of attack we’ve been handling.